I'm new to this self-host stuff so this is probably operator error but, I installed the sparkbox and used the token, I have access to the dashboard but no top menus or access to settings.
12 replies
tomspark wrote:
That console line is the smoking gun — thank you for grabbing it. The dashboard's Content-Security-Policy is blocking its own inline click handlers (that 'script-src-attr was blocked' line), so the navigation never wires up — that's exactly why there's no top menu or Settings. This is 100% on us, not your setup, and it's hitting several people. I'm fixing it at the source (letting the dashboard's own handlers run without weakening real security). There's no clean browser-side workaround for this one, so sit tight — it's top of my list and I'll reply here the moment the fixed build is out. You're on v1.6.116.
tomspark wrote:
Update — fixed, and it's live now in v1.6.118. The missing nav/Settings was our dashboard's own security policy blocking its inline buttons (exactly what your F12 log showed — thank you again for that, it pinned it down). To get the fix: re-run the installer — curl -fsSL https://get.tomsparkbox.com/install.sh | sudo bash — it updates in place and keeps all your data and settings, then hard-refresh the dashboard (Ctrl+Shift+R). Your top menu and Settings will be back. Bonus in this build: the Updates tab now shows a dot when a new SparkBox version is out, so you'll actually see future updates instead of having to check.
tomspark wrote:
Quick follow-up — v1.6.119 is live now, which closes the last CSP gap (the blocked-image line in your console). To pick it up: re-run the installer (curl -fsSL https://get.tomsparkbox.com/install.sh | sudo bash), then specifically restart the dashboard: sudo /opt/sparkbox/sparkbox restart dashboard. That restart is the important part — the updater refreshes the files but the dashboard keeps running the old code until it's restarted, which is most likely why v1.6.118 didn't take for you. Then open the dashboard in a private/incognito window. That combination should finally bring your top menu and Settings back. Let me know either way and we'll keep digging if needed.
tomspark wrote:
That confirms it — the fix is good (incognito proves it), and your normal tabs are just holding the old cached dashboard. A plain refresh doesn't always clear that. To fix the regular browser: open the dashboard, press F12 - go to the Application (or Storage) tab - click "Clear site data" (in Firefox: click the padlock/site-info icon next to the address - Clear cookies and site data), then reload. If there's a "Service Workers" entry there, hit Unregister too. After that your normal tabs will load the new dashboard like incognito does. Glad it's working — thanks for sticking with it through all the back-and-forth!
tomspark wrote:
That's on us, not your setup — a fresh install should show the full top nav and Settings. First quick thing to try: hard-refresh the dashboard with Ctrl+Shift+R (Cmd+Shift+R on Mac). On fresh installs the browser sometimes caches a half-loaded dashboard bundle and the nav never mounts; a hard refresh clears it. If the menu's still missing after that, open the browser console (F12 - Console tab), reload the page, and paste any red error lines here — that pinpoints exactly what's failing to load. Also tell me the version shown at the bottom of the dashboard. You're on a DXP2800; current build is v1.6.115. We'll get it sorted — this is a known dashboard-render issue we're actively working.
lexgrossman wrote:
Copy, tyvm
tomspark wrote:
Anytime — if the hard refresh doesn't bring the nav back, drop that F12 console error here and I'll dig in. We're on it either way.
lexgrossman wrote:
Password fields present on an insecure (http://) page. This is a security risk that allows user login credentials to be stolen. 2 (my IP) Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-7gARHtoi6pAZiAHezIiDSJe/N/vsrnASD6ioNgzCj+w=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-6UhvYu/EQL4/zMWdqY4H6NnMZSaFWzbdjKVw8HLfOro=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-LymVKyJnH9+0Ch+wbh1dauQx32a8Pdz1lX+w4gd0ihg=') together with 'unsafe-hashes'. app.js:1616:5 Content-Security-Policy: The page’s settings block
lexgrossman wrote:
copy, thank you again!
lexgrossman wrote:
Just ran the installer and updated to v1.6.118 and did the hard refresh and still no top menus/ section. console error below password fields present on an insecure (http://) page. This is a security risk that allows user login credentials to be stolen. 2 192.168.8.111:8443 Layout was forced before the page was fully loaded. If stylesheets are not yet loaded this may cause a flash of unstyled content. index.js:1268:1 Content-Security-Policy: The page’s settings blocked the loading of a resource (img-src) at blob:http://192.168.8.111:8443/4f240c41-932c-46cb-ac36-62d1f1db927c because it violates the following directive: “img-src 'self' data:” 192.168.8.111:8443:265:13 The resource at “http://192.168.8.111:8443/icons/wireguard.svg” preloaded with link preload was not used within a few seconds. Make sure all attributes of the preload tag are set correctly. 192.168.8.111:8443
tomspark wrote:
Sorry it's still down — but here's the key thing: I loaded a clean v1.6.118 dashboard myself and the full menu renders with zero errors, so the v1.6.118 fix itself is good. That means your box is almost certainly still running the OLD dashboard — re-running the installer updated the files, but the dashboard service kept running the old code. Two steps: 1. Restart it: sudo /opt/sparkbox/sparkbox restart dashboard (a full NAS reboot also works) 2. Then open the dashboard in a private/incognito window — a normal hard-refresh doesn't always drop cached files; incognito does. If the menu is STILL gone after both, open F12 - Console and paste only the RED error lines (ignore the 'insecure http page' note and the yellow CSP warnings — those are harmless). One more fix for a leftover image-blocking CSP line is shipping as v1.6.119 shortly, but the restart + incognito is what should bring your menu back right now.
lexgrossman wrote:
Hey, did everything and i got the menus back! only in incognito mode, regular tabs are still not showing but thank you very much for your time on this!